# MTradecraft > MTradecraft LLC is a cybersecurity compliance consulting firm for SEC-registered investment advisers, hedge funds, broker-dealers, and family offices. It builds and maintains the cybersecurity compliance program that a firm's SEC examiner, FINRA, state securities boards, insurance carrier, and institutional investors expect to see — mapping every technical finding to a specific regulation (Rule 206(4)-7, Regulation S-P, Regulation S-ID, Rule 204-2). The firm is vendor-independent and evidence-driven: no product, no commission, no bias. Principal: Brian Hahn (Dallas / McKinney, Texas). ## About - [About MTradecraft](https://mtradecraft.com/about/): Brian Hahn founded MTradecraft to bring intelligence tradecraft and Wall Street operational discipline to cybersecurity compliance for SEC-registered firms. - [Home](https://mtradecraft.com/): Overview of MTradecraft's cybersecurity compliance and Remote CISO services for SEC-registered firms. ## Services MTradecraft operates as a "BrainTrust" to its clients — transferring practical knowledge with precision. Engagements: - [Services overview](https://mtradecraft.com/services/): All engagements and pricing. - Cyber Compliance Consultant — $36,000/year: A full cybersecurity compliance program operated on an annual cadence for firms with a Chief Compliance Officer and outsourced IT but no internal security function. Includes external attack surface assessment, internal vulnerability scanning, Microsoft 365/Azure configuration audit, policy and procedure manual, Rule 206(4)-7 annual review, vendor due diligence support, incident response plan, and a maintained evidence file. - Remote CISO — $72,000/year: Everything in the Cyber Compliance Consultant program plus a named Chief Information Security Officer designation, AI compliance governance, an annual penetration test, an annual tabletop exercise, board and management briefings, and 24-hour response. The answer when an insurer, custodian, prime broker, or institutional investor asks who the firm's CISO is. - The BrainTrust — $2,500/year: Self-serve membership giving access to MTradecraft's cybersecurity policy library, templates, frameworks, the AI compliance framework, and FieldCraft security awareness training. - One-time engagements: Cyber Risk & Vulnerability Threat Assessment (CRVT, from $10,000), External Penetration Test (from $8,000), Tabletop Exercise (from $5,000), AI Compliance Framework Build (from $35,000), Microsoft 365/Azure Configuration Audit (from $5,000), Internal Network Vulnerability Scan (from $4,000/location), External Attack Surface Assessment (from $4,000), Policy & Documentation Review (from $3,000), Vendor Due Diligence Questionnaire (from $2,500/vendor), and Incident Response Coordination for non-subscribers ($300/hour). ## Regulatory reference - [Cybersecurity regulations for RIAs, broker-dealers, and financial institutions](https://mtradecraft.com/regulations/): A practical reference to SEC rules (206(4)-7, Regulation S-P, Regulation S-ID, 204-2), FINRA rules (3110, 3120, 4370, 4530, 3310), and state cybersecurity regulations including NYDFS 23 NYCRR Part 500. Key facts: the 2024 Regulation S-P amendments (effective August 2, 2024) require a written incident response program and notification of affected individuals no later than 30 days after a firm becomes aware of a covered incident; compliance deadlines were December 3, 2025 (larger entities) and June 3, 2026 (smaller entities). - [Vendor Due Diligence](https://mtradecraft.com/vendor-due-diligence/): A shared due-diligence knowledge base for the vendors RIAs rely on, supporting SEC vendor-oversight obligations under Regulation S-P and Rule 206(4)-7. ## Insights - [What an SEC Examiner Actually Asks For: The Cybersecurity Document Request List](https://mtradecraft.com/resources/insights/sec-examiner-cybersecurity-document-request-list/): The documents firms are actually asked to produce in an SEC cyber exam, and what each one proves. - [What a Cyber Risk Vulnerability Threat Assessment Actually Involves](https://mtradecraft.com/resources/insights/what-a-crvt-cyber-risk-vulnerability-threat-assessment-involves/): What a CRVT covers, how it is performed, and what it produces — the most-requested document in an SEC cyber exam. - [The New SEC Regulation S-P Amendments: What Every RIA Needs to Know](https://mtradecraft.com/resources/insights/new-sec-regulation-sp-amendments-what-rias-need-to-know/): Plain-language briefing on the written incident response program, the 30-day notification clock, the 72-hour vendor breach standard, and five-year recordkeeping. - [Your Identity Theft Red Flags Program Is Probably a Dead Document](https://mtradecraft.com/resources/insights/identity-theft-red-flags-program-regulation-s-id/): Why most Regulation S-ID Red Flags programs no longer survive an exam, and how to fix them. - [Practical Takeaways from the SEC's M Holdings Cybersecurity Case](https://mtradecraft.com/resources/insights/practical-takeaways-sec-m-holdings-cybersecurity-case/): How the SEC evaluates cybersecurity programs today — enforceable baselines, evidence-based supervision, and incident response that works outside a binder. - [The Betterment Breach: How Modern RIA Breaches Actually Happen](https://mtradecraft.com/resources/insights/betterment-breach-how-modern-ria-breaches-happen/): The modern breach pattern — social engineering of a third-party platform rather than broken encryption. - [How RIAs Should Configure Microsoft for SEC Exams](https://mtradecraft.com/resources/insights/how-rias-should-configure-microsoft-for-sec-exams/): How Microsoft 365 already contains the controls an RIA needs; the gap is configuration and evidence. - [Microsoft 365 and Azure for RIAs: The Deployment Mistakes I Find Almost Every Time](https://mtradecraft.com/resources/insights/microsoft-365-azure-rias-deployment-mistakes/): Five recurring M365/Azure deficiencies in RIA assessments and the benchmark that fixes them. - [AI Deployment in SEC-Registered Firms: Five Pillars and a Control Stack](https://mtradecraft.com/resources/insights/ai-deployment-five-pillars-control-stack/): A practitioner framework for defensible AI decisions under existing SEC rules. - [How the SEC Expects RIAs to Supervise AI — Today](https://mtradecraft.com/resources/insights/how-sec-expects-rias-to-supervise-ai-today/): Ten questions on supervising AI under current SEC rules, answered. - [How a Spy Would Conduct Vendor Due Diligence](https://mtradecraft.com/resources/insights/how-a-spy-would-conduct-vendor-due-diligence/): Intelligence-tradecraft discipline applied to RIA vendor oversight using OSINT. - [Performing a Cyber Risk and Threat Assessment Using Shodan](https://mtradecraft.com/resources/insights/cyber-risk-threat-assessment-using-shodan/): Using Shodan to document external visibility and turn it into the written risk assessment examiners request. - [You Can't Prove Cybersecurity Compliance Without Internal Vulnerability Scans](https://mtradecraft.com/resources/insights/cant-prove-compliance-without-internal-vulnerability-scans/): Why a credentialed internal scan differs from a remote one, and why it matters for SEC compliance. - ["We Have a Plan" Is Not the Same as "We Tested It": Incident Response Tabletops for RIAs](https://mtradecraft.com/resources/insights/incident-response-tabletop-exercises-for-rias/): What a tabletop exercise is, why Regulation S-P requires a workable IR program, and what evidence of testing looks like. - [Cufflinks or Handcuffs: The New Era of Executive Cybersecurity Liability](https://mtradecraft.com/resources/insights/cufflinks-or-handcuffs-executive-cybersecurity-liability/): How cybersecurity became a personal executive liability issue, and five ways executives protect themselves. - [The SEC Exam Is No Longer Your Biggest Problem](https://mtradecraft.com/resources/insights/sec-exam-no-longer-your-biggest-problem/): Why phishing still wins, why MFA so often has holes around it, and why the endpoint is where programs fall apart. - [The Perimeter Is Gone: What AI-Driven Vulnerability Discovery Means for Small RIAs](https://mtradecraft.com/resources/insights/perimeter-is-gone-ai-vulnerability-discovery-small-rias/): What it means when AI systems can autonomously find and exploit vulnerabilities at scale. - [The Unseen Risk of a Stolen iPhone to Your Firm's Network](https://mtradecraft.com/resources/insights/unseen-risk-stolen-iphone-firm-network/): How a single stolen iPhone plus its unlock PIN can cascade into a network compromise under BYOD. - [Why Email Is Still Broken — and What You Can Do About It](https://mtradecraft.com/resources/insights/why-email-is-still-broken/): SPF, DKIM, and DMARC explained, plus a practical tightening checklist for RIAs. - [The Great Data Reclamation: The Future of RIA Operations, Infrastructure, and Security](https://mtradecraft.com/resources/insights/great-data-reclamation-future-ria-operations/): Vendor concentration, AI data absorption, and the quantum decryption threat reshaping RIA risk. ## Contact - Book a call: https://calendar.proton.me/u/5/bookings#aZXq1N2J-Weg-lfdZfL-btpm3M7HZe2bAPcuUlrFNzA= - Email: brian@mtradecraft.com